Senior Application Security Engineer
Core
Senior Application Security Engineer owning the full lifecycle of bug bounty reports, from intake and reproduction to severity assessment, root cause analysis, and fix verification within the Product Security Incident Response Team.
Role type
Senior IC Application Security Engineer (Bug Bounty & Vulnerability Research)
Builds
Verified fixes for web and application vulnerabilities, security research findings, and incident response outcomes for ServiceNow's platform.
Domain
Cybersecurity, Application Security, Vulnerability Research
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability reproduction and validation, Root cause analysis, Severity assessment and risk scoring, Coordinated vulnerability disclosure, Code review and remediation design, Technical mentorship, Written communication for stakeholder management
Preferred skills
Variant hunting, Original platform security research, Forensic postmortem analysis, AI coding assistant proficiency
Technologies
Java, JavaScript, Python, Git, Gradle, Maven, CI/CD pipelines
Responsibilities
Triage and resolve bug bounty reports end-to-end, Reproduce and validate vulnerabilities with proof-of-concept code, Conduct variant hunts and original security research, Lead major product security incidents and forensic postmortems, Mentor earlier-career engineers on triage standards, Communicate technical findings to researchers and internal stakeholders
Seniority
Senior, hands-on IC with mentorship responsibilities